Saudi PDPL vs UAE PDPL: A Comprehensive Comparison
Compare Saudi Arabia's PDPL with the UAE's Federal Decree-Law 45 of 2021. Enforcement maturity, registration, executive regulations, free zones and penalties.
For a group operating across both markets, the asymmetry is the whole story. Saudi Arabia has a complete framework and an active regulator, so obligations are knowable and the cost of getting them wrong is quantifiable today. The UAE has a law in force but an incomplete executive framework, plus two free-zone regimes that displace the federal law entirely depending on where an entity is registered.
Source: IQWorks โ iqworks.ai | Last updated: 2026-08-09
Last verified: August 9, 2026
Saudi PDPL
Saudi Arabia's Personal Data Protection Law is in force with complete Implementing Regulations, a national controller registration platform, and an authority in SDAIA that is actively enforcing.
Pros
- Complete implementing framework, so obligations are knowable today
- Single national regulator with no free-zone carve-outs
- Published enforcement activity gives real signal on priorities
- Dedicated transfer regulations remove ambiguity on cross-border movement
- Registration platform creates a clear compliance checkpoint
Cons
- Legitimate interest unavailable for sensitive personal data
- Registration and periodic assessments add ongoing administration
- Guidance primarily in Arabic
- Criminal exposure raises the stakes for mishandling sensitive data
- Suspension power can interrupt operations
Best For
UAE PDPL
Federal Decree-Law No. 45 of 2021 has applied across the Emirates since January 2022 and is overseen by the UAE Data Office. Its executive regulations remain incomplete, and entities in the DIFC and ADGM free zones fall under separate regimes entirely.
Pros
- Substantive obligations closely track the GDPR, so existing programmes port well
- Full set of data subject rights including portability and objection
- No general controller registration requirement to date
- Mature commercial environment with strong professional services support
- Free zones offer well-understood, GDPR-aligned alternatives
Cons
- Executive regulations still incomplete, leaving operational detail unresolved
- Three separate regimes across mainland, DIFC and ADGM complicate group programmes
- Penalty schedule not yet fully specified
- Limited public enforcement activity to calibrate against
- Entity registration jurisdiction, not data location, determines the applicable law
Best For
Feature Comparison
| Feature | Saudi PDPL | UAE PDPL |
|---|---|---|
| Legal Framework | ||
| Implementing or executive regulations | Complete, published September 2023 | Incomplete as of 2026 |
| In force since | 14 September 2023 | 2 January 2022 |
| Free-zone carve-outs | Yes, DIFC and ADGM operate separate regimes | |
| Obligations | ||
| Controller registration | Required with SDAIA | Not currently required |
| DPO requirement | Where Implementing Regulations criteria are met | Where processing is high risk or involves large volumes of sensitive data |
| Transfer framework | Dedicated Personal Data Transfer Regulations | Detail pending in executive regulations |
| Enforcement | ||
| Regulator | SDAIA | UAE Data Office |
| Maximum administrative fine | SAR 5 million, doubling for repeat violations | To be set by Cabinet resolution |
| Criminal liability | Up to 2 years for malicious sensitive-data disclosure | Not specified in the Decree-Law |
| Enforcement activity to date | Active, with published decisions | Limited public activity |
Our Verdict
The practical consequence is that Saudi work should be scheduled first, because it is both more urgent and better specified. UAE work should not wait for the executive regulations, but it should be built so that the outstanding detail can be slotted in without rework, and every judgment call made in the meantime should be documented with its reasoning.
The entity map matters more in the UAE than almost anywhere else, because registration jurisdiction rather than data location determines the applicable regime. ComplyIQ scopes compliance records per entity, which is what lets one group hold three defensible evidence sets rather than one undifferentiated pile.
Frequently Asked Questions
Which should we prioritise, Saudi or UAE?
Saudi Arabia, in most cases. Its framework is complete and SDAIA is actively enforcing, so both the obligations and the consequences are concrete. UAE work should run in parallel but built to accommodate the executive regulations when they are issued.
Does the UAE federal law cover DIFC and ADGM entities?
No. An entity registered in the DIFC is governed by DIFC Law No. 5 of 2020 and an ADGM entity by the ADGM Data Protection Regulations 2021. The federal Decree-Law applies outside those free zones.
Is controller registration required in the UAE?
There is no general controller registration requirement under the federal Decree-Law comparable to SDAIA's national platform. Registration mechanics were among the details left to the executive regulations.
Can we run one Gulf compliance programme?
Policies, training and security controls can be shared across Saudi Arabia and the UAE. Evidence artefacts cannot: records of processing, consent records and breach registers must be scoped to the entity and producible to the specific regulator that supervises it.